product-vision-steering
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues or malicious patterns were detected in the skill instructions or associated templates.
- [DATA_EXFILTRATION]: The skill scans local project manifest files (such as package.json or pyproject.toml) to determine the project's technology stack and directory structure. This information is used exclusively to populate documentation templates and is only shared with configured documentation platforms following user approval.
- [COMMAND_EXECUTION]: The skill interacts with the filesystem and external documentation services (Confluence, Notion, Azure DevOps Wiki) through authorized MCP tools. These operations are scoped to creating and updating project-specific documentation as requested by the user.
- [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety constraints were identified. The process of gathering project context from codebase files is handled as a metadata extraction task with a human-in-the-loop approval step.
Audit Metadata